CERT home
vulnerabilities & fixesevaluations & practicesresearch & analysistraining & education
homesearchFAQsite indexcontact
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

Vulnerability Note VU#938323

Postfix local privilege escalation

Overview

The Postfix MTA contains a local privilege escalation vulnerability.

I. Description

Postfix is an mail transport agent (MTA) that is used by several Unix-like operating systems. Symbolic links and hard links are types of files that reference other files. Unlike hard links, symbolic links can point to directories and use relative pathnames.

On some non-POSIX.1-2001 and X/Open XPG4v2 compliant systems, users can hardlink symlinks which are owned by the root user. Postfix allows root-owned symlinks to be used as a mail destination folder. A hard link to a Postfix root-owned symlink could point to a file that can be overwritten by Postfix, regardless of the permissions of the destination file.

II. Impact

A local, authenticated attacker may be able to overwrite arbitrary files, possibly gaining elevated privileges.

III. Solution

Upgrade

See http://article.gmane.org/gmane.mail.postfix.announce/110 for information about obtaining updated software. Users who do not compile Postfix from source should see the systems affected section below for a partial list of affected vendors.

Set mailbox permissions

Making the system mail spool directory root-owned may mitigate this vulnerability. See http://article.gmane.org/gmane.mail.postfix.announce/110 for specific information about this and other workarounds.

Systems Affected

VendorStatusDate Updated
Apple Computer, Inc.Unknown19-Aug-2008
Conectiva Inc.Unknown1-Aug-2008
Cray Inc.Unknown1-Aug-2008
Debian GNU/LinuxUnknown1-Aug-2008
DragonFly BSD ProjectNot Vulnerable2-Aug-2008
EMC CorporationUnknown1-Aug-2008
Engarde Secure LinuxUnknown1-Aug-2008
F5 Networks, Inc.Unknown1-Aug-2008
Fedora ProjectUnknown1-Aug-2008
FreeBSD, Inc.Unknown1-Aug-2008
FujitsuUnknown1-Aug-2008
Gentoo LinuxVulnerable18-Aug-2008
Hewlett-Packard CompanyUnknown1-Aug-2008
HitachiUnknown1-Aug-2008
IBM CorporationUnknown1-Aug-2008
IBM Corporation (zseries)Unknown1-Aug-2008
IBM eServerUnknown1-Aug-2008
Ingrian Networks, Inc.Unknown1-Aug-2008
Juniper Networks, Inc.Unknown1-Aug-2008
Mandriva, Inc.Vulnerable18-Aug-2008
Microsoft CorporationUnknown1-Aug-2008
MontaVista Software, Inc.Unknown1-Aug-2008
NEC CorporationUnknown1-Aug-2008
NetBSDUnknown1-Aug-2008
NokiaUnknown1-Aug-2008
Novell, Inc.Unknown1-Aug-2008
Openwall GNU/*/LinuxUnknown1-Aug-2008
QNX, Software Systems, Inc.Unknown1-Aug-2008
Red Hat, Inc.Unknown1-Aug-2008
Silicon Graphics, Inc.Unknown1-Aug-2008
Slackware Linux Inc.Unknown1-Aug-2008
Sony CorporationUnknown1-Aug-2008
Sun Microsystems, Inc.Not Vulnerable19-Aug-2008
SUSE LinuxVulnerable18-Aug-2008
The SCO GroupUnknown1-Aug-2008
TurbolinuxUnknown1-Aug-2008
UbuntuVulnerable19-Aug-2008
UnisysUnknown1-Aug-2008
Wind River Systems, Inc.Unknown1-Aug-2008

References


ftp://ftp.porcupine.org/mirrors/postfix-release/index/html
http://article.gmane.org/gmane.mail.postfix.announce/110
http://linuxgazette.net/105/pitcher.html
http://en.wikipedia.org/wiki/Hard_links
http://en.wikipedia.org/wiki/Symbolic_link

Credit

Thanks to Wietse Venema for information that was used in this report. Sebastian Krahmer of SuSE is credited for discovering and reporting this issue.

This document was written by Ryan Giobbi.

Other Information

Date Public08/18/2008
Date First Published08/18/2008 03:52:50 PM
Date Last Updated08/19/2008
CERT Advisory 
CVE NameCVE-2008-2936
Metric4.20
Document Revision20

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Copyright 2008 Carnegie Mellon University